Heap Out-of-Bounds Write Vulnerability in GStreamer by Red Hat
CVE-2026-19387
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-19387?
A heap out-of-bounds write vulnerability was identified in the GStreamer gst-plugins-bad adpcmdec element during the decoding process of IMA/DVI ADPCM audio. This security flaw stems from insufficient validation of the per-block sample count, particularly for multi-channel streams. An attacker could exploit this by delivering a specially crafted WAV file, leading to writes that exceed the bounds of the allocated output buffer. The potential consequences include application crashes, denial of service incidents, memory corruption, and in certain cases, arbitrary code execution when processing untrusted media.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.7
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-3.el10_0.7
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.10.4-8.el7_9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved